False Alarm Rate 변화에 따른 DoS/DDoS 탐지 알고리즘의 성능 분석

Performance Analysis of DoS/DDoS Attack Detection Algorithms using Different False Alarm Rates
  • 장범수
  • 이주영
  • 정재일

초록

Internet was designed for network scalability and best-effort service which makes all hosts connected to Internet to be vulnerable against attack. Many papers have been proposed about attack detection algorithms against the attack using IP spoofing and DoS/DDoS attack. Purpose of DoS/DDoS attack is achieved in short period after the attack begins. Therefore, DoS/DDoS attack should be detected as soon as possible. Attack detection algorithms using false alarm rates consist of the false negative rate and the false positive rate. Moreover, they are important metrics to evaluate the attack detections. In this paper, we analyze the performance of the attack detection algorithms using the impact of false negative rate and false positive rate variation to the normal traffic and the attack traffic by simulations. As the result of this, we find that the number of passed attack packets is in the proportion to the false negative rate and the number of passed normal packets is in the inverse proportion to the false positive rate. We also analyze the limits of attack detection due to the relation between the false negative rate and the false positive rate. Finally,we propose a solution to minimize the limits of attack detection algorithms by defining the network state using the ratio between the number of packets classified as attack packets and the number of packets classified as normal packets. We find the performance of attack detection algorithm is improved by passing the packets classified as attack

키워드

미탐지율오탐지율오경고율DDoS 공격탐지False negative rateFalse positive rateFalse alarm rateDDoS detection
제목
False Alarm Rate 변화에 따른 DoS/DDoS 탐지 알고리즘의 성능 분석
제목 (타언어)
Performance Analysis of DoS/DDoS Attack Detection Algorithms using Different False Alarm Rates
저자
장범수이주영정재일
발행일
2010-12
저널명
한국시뮬레이션학회 논문지
19
4
페이지
139 ~ 149